Thousands of Palo Alto Firewalls Breached in Exploit Campaign

TL;DR
Approximately 2,000 Palo Alto Networks firewalls have been compromised due to two newly discovered vulnerabilities, CVE-2024-0012 and CVE-2024-9474, which allow attackers to gain unauthorized access and root privileges. Despite a decrease in internet-exposed interfaces, the Shadowserver Foundation reports significant exploitation, primarily in the US and India. Palo Alto Networks has released patches and shared indicators of compromise to help mitigate the threat, while emphasizing that most customers follow best practices to secure their systems.
Topics:businesscybersecurity#cyber-attacks#cybersecurity#firewall-vulnerabilities#palo-alto-networks#security-patches#zero-day-exploit
- 2,000 Palo Alto Firewalls Compromised via New Vulnerabilities SecurityWeek
- Over 2,000 Palo Alto firewalls hacked using recently patched bugs BleepingComputer
- 1000s of Palo Alto Networks firewalls hijacked as miscreants exploit critical hole The Register
- Wiz observes CVE-2024-0012 and CVE-2024-9474 exploitation Wiz
- Warning: Over 2,000 Palo Alto Networks Devices Hacked in Ongoing Attack Campaign The Hacker News
Want the full story? Read the original reporting
Read on SecurityWeek